| Summary | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a transaction.This issue affects ERPNext: 16.16.0. |
|---|---|
| Publication Date | June 4, 2026, 4:16 a.m. |
| Registration Date | June 5, 2026, 4:10 a.m. |
| Last Update | June 5, 2026, 12:23 a.m. |